Chrome browser insecurity
"Viswanathan, Kapaleeswaran (PPS Hub R&D)" <[email protected]>
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <C9AD4A3BD6DF0E47BAB653706DE9847E1A8508A9@G5W2734.americas.hpqcorp.net> |
Chrome extensions violate basic browser security assumptions. This was a remarkable revelation to me, which I least expected. The official claim, which I bought into, that Chrome browser is secure is at the following URL. http://www.google.com/googlebooks/chrome/med_02.html The following website helped me realize the revelation. http://developer.chrome.com/extensions/messaging.html#security-considerations Can there be a Trojan-free log-in page with an insecure Chrome extension? I was also wondering what the security of CAJA may be when considering insecure Chrome extensions. Regards Kapali Viswanathan